Jump to content

mistersparky

Members
  • Posts

    33
  • Joined

  • Last visited

Everything posted by mistersparky

  1. Good morning everyone! I've got a strange issue with auto-processing on some of our Exchange resource mailboxes. These resource mailboxes have all been configured with relatively standard auto-processing rules, however not all meeting requests appear to be accepted automatically, with no clear pattern as to what is and is not accepted. For a given resource mailbox, if I take a look the deleted items I will see multiple meeting requests which correspond to requests that the resource mailbox has received and fall under the in-policy criteria for the resource, and which were automatically accepted and added to the calendar (with the meeting request itself deleted). However, if I look at the inbox for the same resource mailbox, I see multiple meeting requests that also fall under the in-policy criteria, but which for some reason are not auto-accepted by the resource mailbox. Does anyone have any ideas what could be causing this, or what I could test to try and resolve? Thanks in advance for any help with this!
  2. Good evening everyone! I’ve got a question regarding handling the Exchange Online mailboxes for staff leavers. We currently have a hybrid setup with Exchange 2010 on-prem servers running alongside Exchange Online E1 and E3 licenced users. With have Azure AD sync in place to replicate relevant AD details to Office 365. For leavers with on-prem mailboxes, we will disable the account and remove from groups, leave the mailbox active for a few months with necessary auto-replies and forwards in place, then delete the mailbox after a given period of time. With Exchange Online mailboxes, the mailbox is lost within a short period of time of the associated AD account being disabled. I’d like to find a tidy way to disable the accounts as required, whilst maintaining the mailboxes. I believe holds and converting to shared mailboxes are the recommened approach for this, however I’ve got a few questions: Is an Exchange Online license reserved for the duration of a hold on a mailbox? Holds only seem to be available for E3 licenses and above. Is it possible to just upgrade an E1 license to E3 shortly before implementing the hold and disabling the account? Do holds allow mailbox, auto-responses and forwards to run on the mailbox? With the approach of converting to a shared mailbox, what’s the best way to keep track of desired deletion times for such mailboxes? How difficult is it to handle return staff for mailboxes that have been converted into shared mailboxes? Finally, I’d love to hear what approach you take, and the pros and cons of your choice. Thanks in advance for any help or advise!
  3. Some questions on the WiFi front: Does the problem happen more often when using the laptops in the same location, or when using larger numbers of laptops? Do you have good WiFi coverage around the building? What have you done to avoid overlapping 2.4GHz channels (have you had some kind of WiFi survey done, manual settings, or is it managed by the WLC?) How much is connecting via 802.11b/g? I've seen some strange situations where 802.11b/g/2.4Ghz n devices with faults/poor signal can drop the bandwidth across the SSID (I think a common workaround for this is to data rates than 11Mb/s for the 2.4 GHz 802.11b/g/n networks). I had a lot of problems a few years ago with a situation not to dissimilar to this that, much to my frustration, I was unable to resolve. Some of the details of this eppisode can be found here: http://www.edugeek.net/forums/windows-server-2008-r2/108941-roaming-profie-oddities.html. The biggest takeaway I took from all of this is a lot of functionality one would associated with a managed Windows desktop environment (roaming profiles, folder redirection, network drives, other general GPO policies, etc.) simply don't work well over low bandwidth, poor signal WiFi networks. It might be somewhat stating the obvious, but I think it would be good to start from checking the WiFi network. Is coverage as good as it can be, are there any settings or tweaks you can put in place to improve the network? Is it possible to get any users to connect over wired connections?
  4. Assuming this is a VM, is the VM itself set to sync time with the host? You can find the options for this here: In general, I've always avoided this and stuck with the built-in time functionality within Windows. However, it would still be highly advisable to configure the ESXi hosts to sync to a valid time source (if you are not doing so already), to avoid issues such as this, maintain accurate log times, etc.
  5. A few follow-up questions: What OS iis the server? How behind (if at all) are you on Windows Updates? What version of VMware tools are installed? Is the server running anything else other than print services? For the drivers already installed, what driver isolation is configured? Where is the OS getting stuck during the long restarts? (check via vSphere console)
  6. Good morning everyone! We have a number of users with access to shared mailboxes. These mailboxes are usually added as secondary mail accounts, in online mode, within Outlook 2013 clients. Users are reporting that view settings for these shared mailboxes synchronise between users. So, if a user applies a particular filter or sorting to the shared mailbox, these view settings syncronise across all users of the shared mailbox. Is there any way to have view settings for such shared mailbox to be local, and not synchronise across all users of the shared mailbox? Thanks in advance for any help with this!
  7. Hello everyone, I have the following server: HP DL360p G8 Latest BIOS and drivers ESXi 5.5 U1, HP custom image, latest update patches. Running in stand-alone mode (no vCentre Server). Windows Server 2008 R2 Standard, latest updates. 53c1030 PCI-X Fusion=MPT Dual Ultra320 SCSI card HP Ultrium 2 SCSI tape drive Backup Exec 2010 R3 I am trying to use all of the above to run backup file shares and Exchange MBs from another server. To even get an active path on the SCSI adapter to the tape drive I had to run the commands form this thread: https://communities.vmware.com/message/2307054. With the tape drive installed I am now getting pretty terrible results trying to backup to tape. Every once in a while a job will finish, but most commonly they will either fail (with the file share backups often failing during the verify phase), or simply time-out, with the tape drive itself appearing to go offline. Once in this state, a host restart is required to release whatever lock is in place on the tape drive. I have tried different drivers (HP and Symantec), different SCSI BIOS settings, trying to match SCSI IDs to VMware device IDs (there are a few links that suggest this as a solution) and also running the SCSI card in bypass mode on the ESX host (the VM wouldn’t even boot with this configured). None of these things seem to make much of a difference to the success rate of backup jobs.Any ideas as to what could be causing this? I’d be very grateful for any suggestions!
  8. Hello everyone! I am looking at configuring a fresh set of directories for user home folders & documents redirection. I have a few questions about the finer permissions of this process. In the past, I have always followed the Microsoft TechNet “Security Recommendations for Folder Redirection” guide (Security Recommendations for Folder Redirection: Group Policy). However, I have noticed that an increasing number of sources recommend “Read Attributes” and “Traverse Folder/Execute File” permissions for users at the root of the share, in addition to “Create Folder/Append Data” & “List Folder/Read Data”. I have also noticed a couple of sources recommending adding further permissions, such as “Read Extended Attributes” & “Read Permissions”. Which of these is the best option? What considerations are there for taking the various approaches? Second of all, most sources indicate that “Creator Owner” should be given full control of subfolders and files from the root of the documents share. This should give users the ability to change ownership and permissions on their files – do they actually need full control or would modify permissions suffice? Thanks in advance for any help with this issue.
  9. Good morning everyone! We currently run Active Directory Certificate Services across our domain. We have a stand-alone root certificate authority and a single intermediate certificate authority. We use Group Policy to deploy the root and intermediate certificates to workstations and auto-enrol the workstations using the “Computer” template. We are looking to expand upon this setup by adding a second intermediate certificate authority from the root that at the least can serve a separate site and at best can provide some redundancy for certification requirements. However, I am unclear on some of the mechanics of this and relevant documentation appears sparse. A few questions: I don’t see anywhere in Group Policy where I am able to actually specify what intermediate CA to enrol with. I am assuming that this is dictated simply by which intermediate certificates are published via Group Policy? If this is correct, if we wanted to have workstations enrol with multiple intermediate CAs would it just be case of publishing each of them via GP? Is there any way to influence which of the two intermediate CAs a workstation will enrol with? Is it possible to set up cross-certification, where certificates from one intermediate are trusted by the other? Is there any way to have a workstation enrol with more than one intermediate CA? Thanks in advance for any help with this enquiry!
  10. Good morning everyone! I am currently in the process of creating dedicated accounts for a number of services that currently use domain admin credentials. One of these is DNS dynamic updates. The domain itself is 2003 functionality level, with 2003 DCs and DHCP and DNS on DCs. Taking a look on the MS MVPs website (DHCP, Dynamic DNS Updates , Scavenging, static entries & time stamps, the DnsUpdateProxy Group, and DHCP Name Protection - AD and Exchange Quantum Singularity), I believe I need to do the following: Add DHCP DC to DnsUpdateProxy security group. Change DHCP to update all records. Secure update settings are already in place, so no need to change this. Create a standard domain user account and configure DNS dynamic updates to use this. Clear all current DNS entries. No 2008 R2 servers, so no securing DNS update proxy group or name protection. Can anyone spot anything missing from this list? If not, that looks like quite a lot of change to enable a least privilege service account, and quite possibly a number of negative security changes. Would it be better to just create a service account with sufficient permissions to update DNS records, when required? If so, what permissions would such a service account require? Thanks in advance for any help with this enquiry.
  11. The old network manager understands well enough as they (me!) have worked in IT in education for a decade, including 2 years in this role. Ultimately, the call to make it part time was not mine. As to whether it the right call or not, I would quote pantscat: 650 students, 150 or so staff, just under 600 end devices. So, not big but not small either. I think it's a relatively well-oiled ship, although there will certainly be challenges moving forwards. The ICT techs are also pretty good, and have been getting increasingly involved in higher level tasks over the last 18 months. I think ultimately the job will be whatever the new NM makes of it, and the role is a great opportunity for someone who is looking for something that matches the time requirements.
  12. Nope. The position was full time on a lower scale, but it was decided with the old network manager (me!) moving on that the nature of the role would be changed. In addition to the network manager role, there are two full time network technicians in place.
  13. As title, an opening for the Head of Technical Support/Network Manager at Christ's College, Guildford. Permanent Contract. 15 hours a week. 52 weeks a year with 24 days (pro – rata) annual leave. Pay: Pro–rata to SP10 in the range £36,965 - £41,942 depending on experience. Actual salary based on minimum point: £15,402. Full job description here - http://www.christscollege.surrey.sch.uk/user/74/112973.pdf. Application form here - Vacancies. Please feel free to drop me a line with any questions!
  14. OK, a few updates: We have deployed a GPO to disable slow link detection on all workstations across the domain We have added the Microsoft KB2775511 updates to our WSUS server to deploy to all workstation PCs - however, we cannot deploy these fixes to our user and roaming profile fileshares as they are currently running on 2008, not 2008 R2 servers. This update is now on 75% of our workstations and counting. However, I am pretty sure we are getting problems both on PCs it is and is not installed on We are still getting a slow but steady stream of students with folder redirection settings going missing. I don't think we have once had this for a member of staff, with the only major difference between these users being students heavy use of wireless networks. Could this be related to laptops sleeping/now shutting down, as opposed to general wireless logon attempts? We are using DFS-N for our roaming profile and are not using FQDNs for these shares when configuring the profiles. I would be more concerned about both if it were not for the fact that our staff users pretty much never exerience these issues I've tracked a good number of logins for users who are having these issues, and there seem to be a good number of similarities: ntuser.ini file in the root of the users roaming profile resetting to not include the folders configured in GP to not be included in the users roaming profile Multiple missing keys under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer in the users ntuser.dat registry file, including User Shell Folders and Shell Folders Event Viewer logs similar to the ones below (taking out direct references to our domain, usernames and directory paths): This has been going on for far too long now, creating extra work and hassle for our users. We would really like to get to the bottom of the issue and in turn would greatly appretiate any help in getting it fixed. Many thanks for the reply. As mentioned, we are deploying the updates across our network now. There are some really great suggestions in there about wireless. Some of them we already do (non-overlapping channels), some of them we don't but at some point I would like to (such as the seperate VLAN for wireless devices, they currently share our student PC vlan). However, although I am pretty confidant that the problem is being created by users logging in on wireless domain devices, shouldn't there be a difference between "now working very well/general slowness" and flat out "breaking things"?
  15. Thoes settings look OK to me. Certainly the DNS settings are set the same as on our DHCP server, although I know some people say that having the DHCP server manage DNS entries might not be the best thing. The scavange settings also look OK, although off the top of my head I cannot remember best practice for ratios of DHCP leases, refresh and non-refresh times. There is a pretty good guide here that covers the lot - DHCP, Dynamic DNS Updates , Scavenging, static entries & time stamps, the DnsUpdateProxy Group, and DHCP Name Protection - AD and Exchange Quantum Singularity One more quick question - I take it the mac addresses for the network adaptors on the host PCs match the uniquie ID entries on the DHCP leases? One thing you could try - deleting forward and reverse entries for a single device in that address scope with a missing name entry in DHCP (ideally a test PC or similar) then restarting it. See if creating a new entry in DNS (as opposed to refreshing an exsiting entry) solves the problem. It probably won't, but it's an easy thing to try that shouldn't break anything else.
  16. We setup our roaming profile permissions as per the article here - Security Recommendations for Roaming User Profiles Shared Folders: Group Policy. Its a little dated, but it all makes perfect sense and works just fine for us.
  17. I take it you have set the DHCP server to update DNS records? If so, have you done so for all DHCP leases, or just for leases when the clients request so? It might also be worth checking the current IP address of the devices in question (either from the clients themselves or the DHCP server), and see if there are any clashes in DNS with this address - particularly in reverse lookup. If so, check the permissions of these entries against other entries and see if there are any discrepancies.
  18. We have been struggling with this on and off for the last week or so. The first time it was noticed on a relatively open network share, so we just assumed that a user had inadvertantly made the changes. After the second time we set about investigating it, and quickly found the files that the shortcuts were opening along with the "legitimate" target. I think a good starting point is to do a full scan of whatever directory is storing the suspect infected files (not the shorcuts, but the "bonus" files these shortcuts are pointing to). They are usually marked as hidden and system files, so you will need to "show hidden" and "not hide system files" to see them. For us, there were half a dozen suspect files in these directories, all created at the same time. If scans of these folders come up clean (ours initially did), submit samples to your AV provider. For any Sophos users, thats here - http://www.sophos.com/support/samples. For us, this got the files in question classified and within 30 minutes we had IDE updates that could detect and remove it. In addition to updating and scanning both servers and end devices, we started running a handy tool from Sophos called Sophos Source of Infection Tool, which gives names, timestamps and IP addresses of files being writted to specified directories. Running this on network fileshares helped us identify and clear infected hosts.
  19. Hey there everyone! Over last summer we completed a rollout of Windows 7 across our school, which went generally pretty well. As part of this rollout, we made quite a few changes to user accounts, which is one of the few things we are still struggling with. A little bit about the current setup. We have separate DFS “User” shares for students and staff, with each user having their own directory. We use folder redirection to store Documents (inc Music, Pictures and Videos), Favourites, Desktop and Roaming AppData directories separately within these user shares, with user home folders also pointing to the Documents directory. Students and staff both have non-mandatory profiles. In addition to folder redirection, we apply a number of Group Policy settings to configure and secure user accounts. Some of these are policies that we implemented from the start and some of these are policies that we have implemented since then. Some of the more notable polices: • Exclude directories in Roaming Profile - Local Settings;Temporary Internet Files;History;Temp • Do not log users on with temporary profiles (enable) • Allow or Disallow use of the Offline Files feature (disable) • The folder redirection polices are set to not grant users exclusive rights to directores, to not move contents to new location and to leave contents on policy removal. Now, this set works a treat for staff. Roaming profile directories remain small, login times are fast, applications work across workstations without faults and folder redirection seems to stick with users. However, it’s far less reliable for students, who seem to experience the following issues: • Folder redirection seems to drop and stay dropped for a small, but not insignificant number of students. The Documents/Downloads/Roaming AppData/Favourites/Desktop directors (or some combination thereof) on student accounts reset and point to the local profile. Upon logoff, these sync back to the Roaming Profile share. • Local and LocalLow AppData directores seem to be syncing back to some student roaming profile directories, despite them being excluded from doing so in GP. In turn, this causes effected Roaming Profiles to grow considerably in size, with all sort of unwanted nonsense in the roaming profile syncing during login (temp internet files, OST files and so on). The affected users seem to have the entry “[General]ExclusionList=Local Settings;Temporary Internet Files;History;Temp” in their ntuser.ini files, with unaffected users having the entry “[General]ExclusionList=AppData\Local;AppData\LocalLow;$Recycle.Bin;Local Settings;Temporary Internet Files;History;Temp” • Profile resets seem to fix the issue - archiving effected users Roaming Profile and re-directed Roaming AppData directories and letting the profile recreate itself on next login. However the issue seems to resurface for a number of users. I am not sure if this users doing again whatever it was they did in the first place to cause the problem, or whether it’s because they are logging back onto PCs with “corrupt” Roaming Profiles, which copy back to the Roaming Profile share, and in turn follow users to the next PC they use. OK, so moving forwards I have three questions: • One of the few differences between students and staff use of IT is laptops. Students use them a lot, staff use them rarely. Our wireless network also isn’t the best, with generally pretty poor performance. After a quick look around, I found some information on Slow Link Detection GP settings. It seems that this is on by default, and that slow links could very well mean no Folder Redirection (Specifying Group Policy for Slow Link Detection: Group Policy). Could this be what is causing the reset Folder Redirection for our students? Is it the case that any such settings applied during logins over slow links can sync back to the Roaming Profile shares and follow users to other devices? • Is it likely that profile resets to fix affected users are being undone by users logging into PCs they used before we reset their profile? If so, would it be best to look at implementing the “delete profiles older than specified number of days” GP temporarily to a low number to clear out troublesome cached profiles? Could the “Prevent Roaming Profile changes from propagating to the server” GP be a useful tool here for fixing the issue? • Last of all, what could be causing the Local and LocalLow AppData directories to decide to copy back to the Roaming Profile share? How much of a clue are the different ntuser.ini files – could this be another cached profile problem, where fixed profiles are unfixed by users login onto devices with unwanted ntuser.ini settings? It would be really great to get to the bottom of this, and have student accounts work as well as they do for staff. Many thanks in advance for any help and advice!
  20. Holy necro, batman! I have spent a little time trying to deploy Mirosoft Expression Web Studio Pro 4 this week, and ran into this exact same problem. The solution provided worked a treat. However, I think I may have found another way around the problem. There are some good general technical details on the issue here - More Implicit Uses of CAS Policy: loadFromRemoteSources - .NET Security Blog - Site Home - MSDN Blogs, including a few solutions. The last of these solutions was to create a .config file (in this case, XSetup.exe.config), place it in the same directory as the XSetup.exe file, and edit it to include the following: Then, call the application from the network install point as usual, in this case "XSetup.exe -q -manifest:WebStudioManifest.cab" For me at least, this installed the application via a network drive without issue. I don't think it creates any gaping security holes in the application or one's network - if this is not the case, please let me know.
  21. Woop - that worked! Thanks!
  22. Not wanting to hijack the thread here, but do you mean during the post OS instalation where the PC is logged in with a local account and installing applications and so forth? That's something we have always wanted to change, but have not been able to in MDT2010. We have just upgraded to 2012, and if its possible, I would love to know how.
  23. Another vote for MTD here. We started to use WDS on its own, and although we managed to do quite a bit with it, MDT is a lot more advanced and feature rich. There are an awful lot of resources out there on it (many of them are listed in this board’s sticky - http://www.edugeek.net/forums/o-s-deployment/76099-mdt-resources.html). A great place to start might be the MDT 2010 Lite Touch Unleashed videos from Deployment Research/Johan Arwidmark - LTIUnleashedVideos
  24. Hey there everyone! I have a question regarding integrating the installation of Visio and Project into Office 2010 Pro Plus via MDT. I can get stand alone installations of either Office, Project or Visio via MDT deployments work fine: - Create MDT application by copying source files from the appropriate CD - Configure the installation with the OCT (Office Customization Toolkit) - Set application to install during OS deployment by either setting it as a mandatory application in CustomSettings.ini, or adding it as an application entry in the task sequence Is there any way to combine the installations of Office 2010, Project and Visio? I can combine the source installation CDs, import the entire directory into a single MDT application listing and even leave separate MSP files for Office, Project and Visio in the /Updates directory. However, if I don’t specify which product I would like to install, I am prompted to do so during deployment. I can add separate MDT applications entries in from the same MDT applications directory, but this seems to create issues with how and what order MSP files are run from the Updates directory. It doesn’t appear to be possible to import the settings for the separate installations into the same MSP file. Is there any way of properly combining these installations via MDT, or do I just need to keep separate directories with separate MDT application entries? Thanks in advance or advice on this query any help with this.
  25. We use this too, and it works pretty well for us. We manage to recover a good proportion of damaged and deleted files from broken and formatted drives. There might very well be better products out there, but I think you could do a lot wose than this.
×
×
  • Create New...